July 9, 2026
- Esri ArcGIS Server (CVE-2026-9181), a critical pre-auth path traversal through a crafted
itemNameparameter, lets remote attackers read sensitive files on versions up to 12.0; Horizon3 published attack analysis. horizon3.ai · Vulnerabilities & Exploits
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro